{"id":4378,"date":"2025-06-03T10:01:03","date_gmt":"2025-06-03T10:01:03","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/06\/03\/sentinelone-global-service-outage-root-cause-revealed\/"},"modified":"2025-06-03T10:01:03","modified_gmt":"2025-06-03T10:01:03","slug":"sentinelone-global-service-outage-root-cause-revealed","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/06\/03\/sentinelone-global-service-outage-root-cause-revealed\/","title":{"rendered":"SentinelOne Global Service Outage Root Cause Revealed"},"content":{"rendered":"<p>    SentinelOne Global Service Outage Root Cause Revealed<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybersecurity company SentinelOne has released a comprehensive root cause analysis revealing that a software flaw in an infrastructure control system caused the global service disruption that affected customers worldwide on May 29, 2025.<\/p>\n<p>The outage, which lasted approximately 20 hours, was fully restored by May 30 at 10:00 UTC, preventing customers from accessing the SentinelOne management console and related services.<\/p>\n<p>However, their endpoint protection remained operational throughout the incident. The company has confirmed this was not a security-related event, and no customer data was lost.<\/p>\n<p>According to the official analysis, the disruption occurred when critical network routes and DNS resolver rules were automatically deleted due to a software flaw in a soon-to-be-deprecated control system.<\/p>\n<h2 class=\"wp-block-heading\" id=\"technical-root-cause\"><strong>SentinelOne Global Service Outage<\/strong><\/h2>\n<p>The incident began at 13:37 UTC on May 29 when the faulty system was triggered by the creation of a new account during SentinelOne\u2019s ongoing transition to a new Infrastructure-as-Code (IaC) architecture.<\/p>\n<p>\u201cA software flaw in the control system\u2019s configuration comparison function misidentified discrepancies and applied what it believed to be the appropriate configuration state, overwriting previously established network settings,\u201d the company <a href=\"https:\/\/www.sentinelone.com\/blog\/update-on-may-29-outage\/#heading-1\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">explained<\/a>. The deprecated system restored an empty route table, causing widespread loss of network connectivity across all regions.<\/p>\n<p>The outage significantly impacted security teams\u2019 ability to manage their operations, though endpoint protection continued uninterrupted.<\/p>\n<p>Customer <a href=\"https:\/\/cybersecuritynews.com\/sentinelone-outage\/\" target=\"_blank\" rel=\"noreferrer noopener\">reports began<\/a> flowing to SentinelOne Support at 13:55 UTC, just 18 minutes after the initial system failure. Engineering teams identified missing routes on Transit Gateways by 14:27 UTC and immediately began restoration efforts.<\/p>\n<p>SentinelOne\u2019s communication strategy encompassed multiple channels, including announcements on their Customer Portal, email notifications to all customers and partners, social media updates on platforms such as Reddit, and blog posts to keep stakeholders informed throughout the recovery process.<\/p>\n<p>Console access was restored by 20:05 UTC, with full service restoration achieved approximately 14 hours later.<\/p>\n<p>The company has implemented several corrective measures following the incident. SentinelOne is auditing EventBridge and other automatically triggered functions to prevent the deprecated control code from being activated during their architectural transition.<\/p>\n<p>The company is also accelerating its migration to the new IaC infrastructure to eliminate the risks associated with running split architectures.<\/p>\n<p>Additionally, SentinelOne has backed up all Transit Gateway configurations and is improving recovery automation to prevent manual restoration delays in future incidents.<\/p>\n<p>The company is also developing an independently operated public status page and has updated high-severity incident playbooks to ensure better customer communication.<\/p>\n<p>Notably, Federal customers using GovCloud environments were completely unaffected by this incident, though they were notified for transparency purposes. This highlights the segregated nature of SentinelOne\u2019s infrastructure designs for different customer segments.<\/p>\n<p>The incident underscores the complexities technology companies face when modernizing critical infrastructure while maintaining service continuity and demonstrates the importance of robust incident response procedures in cybersecurity operations.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Celebrate 9 years of ANY.RUN!\u00a0<strong>Unlock the full power of<\/strong>\u00a0TI Lookup plan (100\/300\/600\/1,000+ search requests),\u00a0and\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=linkedin_csn&amp;utm_medium=post&amp;utm_campaign=spring_offer&amp;utm_content=plans&amp;utm_term=290525\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">your request quota will double<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/sentineloneoutage-root-cause\/\">SentinelOne Global Service Outage Root Cause Revealed<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/sentineloneoutage-root-cause\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SentinelOne Global Service Outage Root Cause Revealed Cybersecurity company SentinelOne has released a comprehensive root cause analysis revealing that a software flaw in an infrastructure control system caused the global service disruption that affected customers worldwide on May 29, 2025. The outage, which lasted approximately 20 hours, was fully restored by May 30 at 10:00 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-4378","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4378"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4378"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4378\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4378"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4378"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4378"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}